Hunt Host Header

"Hunt Host Header Injection — password reset poisoning → ATO, web cache poisoning via unkeyed Host/X-Forwarded-Host, routing-based SSRF (Host picks upstream → cloud metadata/internal services), path-override SSRF/ACL-bypass (X-Original-URL/X-Rewrite-URL), OAuth redirect_uri/issuer poisoning, and absolute-URL link poisoning in emails. High to Critical when it reaches ATO or mass cache poisoning. Bu

wufufu770 Updated

File contents

wufufu770/skills/tree/main/ext/2-web-vulns/040-hunt-host-header commit e8dcf75fa5

Frequently asked questions

npx skillmds@latest add wufufu770/hunt-host-header-2